<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advise needed for PIX+Squid Proxy configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383061#M558932</link>
    <description>&lt;P&gt;Senario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Squid proxy at DMZ of PIX (single legged).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside LAN: 192.168.22.0 /24&lt;/P&gt;&lt;P&gt;DMZ       : 172.16.10.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to go ahead to configure PIX acl to forward all http, https, ftp traffic iniated from inside LAN to Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq www &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq https&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any range 20 21 &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq www 192.168.22.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq https 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy range 20 21 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp 192.168.22.0 255.255.255.0 host proxy eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this config works?&lt;/P&gt;&lt;P&gt;Any expert to help out there?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:06:23 GMT</pubDate>
    <dc:creator>wanghmk1223</dc:creator>
    <dc:date>2020-02-21T08:06:23Z</dc:date>
    <item>
      <title>Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383061#M558932</link>
      <description>&lt;P&gt;Senario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Squid proxy at DMZ of PIX (single legged).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside LAN: 192.168.22.0 /24&lt;/P&gt;&lt;P&gt;DMZ       : 172.16.10.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to go ahead to configure PIX acl to forward all http, https, ftp traffic iniated from inside LAN to Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq www &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq https&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any range 20 21 &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq www 192.168.22.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq https 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy range 20 21 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp 192.168.22.0 255.255.255.0 host proxy eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this config works?&lt;/P&gt;&lt;P&gt;Any expert to help out there?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383061#M558932</guid>
      <dc:creator>wanghmk1223</dc:creator>
      <dc:date>2020-02-21T08:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383062#M558935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;anyone? help pls?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Apr 2005 13:28:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383062#M558935</guid>
      <dc:creator>wanghmk1223</dc:creator>
      <dc:date>2005-04-26T13:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383063#M558941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look good but you need also DNS !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit udp host proxy any eq 53&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq www&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any eq https&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy any range 20 21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in deny tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list inside_in deny tcp any any eq https&lt;/P&gt;&lt;P&gt;access-list inside_in deny tcp any any range 20 21&lt;/P&gt;&lt;P&gt;access-list inside_in permit tcp 192.168.22.0 255.255.255.0 host proxy eq 8080 &lt;/P&gt;&lt;P&gt;access-list inside_in permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should work ! Reconfigure the Internet Browsers to use the proxy server on port 8080.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove this line if the DMZ does not really does establish connections to the inside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq www 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy eq https 192.168.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list dmz_in permit tcp host proxy range 20 21 192.168.22.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Apr 2005 23:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383063#M558941</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2005-04-26T23:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383064#M558945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much. Will try and let you know.&lt;/P&gt;&lt;P&gt;Thanks once again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2005 00:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383064#M558945</guid>
      <dc:creator>wanghmk1223</dc:creator>
      <dc:date>2005-04-27T00:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383065#M558947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did it work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sincerely&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2005 13:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383065#M558947</guid>
      <dc:creator>Patrick Iseli</dc:creator>
      <dc:date>2005-04-27T13:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Advise needed for PIX+Squid Proxy configuration</title>
      <link>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383066#M558950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No really. i shd allow LAN (tcp) -&amp;gt; proxy using port 8080 first then applied all deny to http,https,ftp. etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the problem is the window authentication (win2k3 active directory) at inside LAN whereas proxy is at DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what ports shd i allow between both to get the proxy auth. works with my win2k3 active directory?&lt;/P&gt;&lt;P&gt;is it only tcp 445 and 88 + udp 88 only ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone can advise?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Apr 2005 00:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/advise-needed-for-pix-squid-proxy-configuration/m-p/383066#M558950</guid>
      <dc:creator>wanghmk1223</dc:creator>
      <dc:date>2005-04-29T00:50:24Z</dc:date>
    </item>
  </channel>
</rss>

